- 专利标题: Virtual patching in a label-based segmented network environment
-
申请号: US16553137申请日: 2019-08-27
-
公开(公告)号: US11516242B2公开(公告)日: 2022-11-29
- 发明人: Rupesh Kumar Mishra , Pritesh Kothari
- 申请人: Illumio, Inc.
- 申请人地址: US CA Sunnyvale
- 专利权人: Illumio, Inc.
- 当前专利权人: Illumio, Inc.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: Fenwick & West LLP
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; H04L9/40 ; H04L47/20 ; G06F8/65 ; H04L67/561 ; H04L67/563
摘要:
A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.
公开/授权文献
信息查询